Weekly Update 399

Presently sponsored by: Kolide believes that maintaining endpoint security shouldn’t mean compromising employee privacy. Check out our manifesto: Honest Security.

The Post Millennial breach in this week’s video is an interesting one, most notably because of the presence of the mailing lists. Now, as I’ve said in every piece of communication I’ve put out on this incident, the lists are what whoever defaced the

Continue reading Weekly Update 399

Weekly Update 398

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How many different angles can you have on one data breach? Facial recognition (which probably isn’t actual biometrics), gambling, offshore developers, unpaid bills, extortion, sloppy password practices and now, an arrest. On pondering it more after today’s livestream, it’s the unfathomable stupidity of publishing

Continue reading Weekly Update 398

Weekly Update 397

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Banks. They screw us on interest rates, they screw us on fees and they screw us on passwords. Remember the old “bank grade security” adage? I took this saying to task almost a decade ago now but it seems that at least as far as password advice goes,

Continue reading Weekly Update 397

Weekly Update 396

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

“More Data Breaches Than You Can Shake a Stick At”. That seems like a reasonable summary and I suggest there are two main reasons for this observation. Firstly, there are simply loads of breaches happening and you know this already because, well, you read my stuff! Secondly, There

Continue reading Weekly Update 396

Weekly Update 395

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Data breach verification: that seems like a good place to start given the discussion in this week’s video about Accor. Watch the vid for the whole thing but in summary, data allegedly taken from Accor was published to a popular hacking forum and the headlines inevitably followed. However,

Continue reading Weekly Update 395

Weekly Update 394

Presently sponsored by: Kolide ensures only secure devices can access your cloud apps. It’s Device Trust tailor-made for Okta. Book a demo today.

I suggest, based on my experiences with data breaches over the years, that AT&T is about to have a very bad time of it. Class actions following data breaches have become all too common and I’ve written before about how much I despise them. The trouble

Continue reading Weekly Update 394

Weekly Update 393

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A serious but not sombre intro this week: I mentioned at the start of the vid that I had the classic visor hat on as I’d had a mole removed from my forehead during the week, along with another on the back of my hand. Here in Australia,

Continue reading Weekly Update 393

Weekly Update 392

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Let’s get straight to the controversial bit: email address validation. A penny-drop moment during this week’s video was that the native browser address validator rejects many otherwise RFC compliant forms. As an example, I asked ChatGTP about the validity of the pipe symbol during the live

Continue reading Weekly Update 392

Weekly Update 389

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How on earth are we still here? You know, that place where breached companies stand up and go all Iraqi information minister on the incident as if somehow, flatly denying the blatantly obvious will make it all go away. It’s the ease of debunking the “no breach

Continue reading Weekly Update 389

Weekly Update 388

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It’s just been a joy to watch the material produced by the NCA and friends following the LockBit takedown this week. So much good stuff from the agencies themselves, not just content but high quality trolling too. Then there’s the whole ecosystem of memes that have

Continue reading Weekly Update 388